Marking as security due to potential abuse by spammers.
We really should hide the profiles and profile pictures of disabled users. I think we should do this non-destructively, hide them by checking the disabled flag then hiding the UI elements. That would allow for a profile that's restored to have the same information as before - AKA if a user is accidentally disabled by a rogue admin account then that user can be re-enabled without loosing anything.
This will be easy for profile descriptions (as they're in one place). This will be hard for profile pictures (as they're all over).